TL;DR: Weak visibility leaves least privilege unenforceable in practice: analysis of 225 companies found 85% of privileged credentials, nearly 1 in 3 users with access, and 15% of accessible resources went unused over 90 days, according to StrongDM. The governance problem is no longer whether least privilege is sound, but whether identity teams can measure real usage fast enough to remove standing risk.
Editorial analysis by NHI Mgmt Group, based on content published by StrongDM: “3 Reasons Why Least Privilege Has Failed”.
By the numbers:
- 85% of credentials with privileges have not been used in the last 90 days.
- Nearly 1 in 3 users with access to systems have not used that access in the last 90 days.
- 15% of resources available have not been accessed in the last 90 days.
Key questions
Q: What breaks when least privilege is based on entitlement lists instead of real usage?
A: Least privilege becomes hard to enforce because the team is optimising for what was granted, not what is still needed.
Q: Why do unused privileged credentials still matter to IAM teams?
A: Unused privileged credentials matter because privilege is the risk, not activity alone.
Q: How do security teams know whether least privilege is actually working?
A: Least privilege is working when identities have narrowly scoped permissions, unused credentials are removed or quarantined, and repeated access reviews consistently shrink entitlements.
Practitioner guidance
- Audit privileged access by last-use date Build review workflows around credentials and roles that have not been exercised in 90 days.
- Separate granted access from actual usage Track which users and systems are granted access, then compare that to real authentication or query activity.
- Remove unnecessary privileged credentials Deprovision credentials that have no current business justification, especially where the same systems can be reached through a narrower role or a different workflow.
Bottom line: The core problem is not whether least privilege is valid, but whether teams can prove which access is still needed.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Visibility debt is now an access-control problem, not just a reporting problem: least privilege cannot be enforced from entitlement records alone when teams cannot observe actual usage. That gap leaves organisations with policy on paper but no proof that access is still needed. The practitioner conclusion is that usage visibility has become part of the control, not merely evidence for the control.
A few things that frame the scale:
- 97% of NHIs carry excessive privileges, increasing unauthorised access and broadening the attack surface, according to the Ultimate Guide to NHIs.
- 92% of cloud identities are over-permissioned and 62% are dormant.
A question worth separating out:
Q: What should organisations do with resources that are never accessed?
A: They should treat never-accessed resources as candidates for retirement, isolation, or stricter containment. Unused assets still expand the reachable environment, so reducing them lowers both exposure and the work required to govern access properly.
👉 Read our full editorial: Least privilege has failed because visibility still lags access